200-201 Security Monitoring Practice Question
An analyst is investigating a potential security incident and reviews the Cisco ASA firewall logs. The logs show the following entry: 'Deny tcp src outside:203.0.113.5/443 dst inside:10.1.1.10/3389'. Which of the following does this log entry indicate?
⚠ Common exam trap
The trap here is misreading the direction of the connection or confusing the source port with the destination port, leading to an incorrect interpretation of the log entry.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An external host attempted to connect to an internal host on RDP, but the connection was blocked by the firewall.
The Cisco ASA log entry shows a denied TCP connection from an external IP address to an internal IP address on port 3389, which is the default port for RDP. The 'Deny' action indicates the firewall blocked the attempt. This is a common scenario where an external host tries to exploit RDP, but the firewall prevents it. Understanding log format, including source/destination and port numbers, is essential for incident analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An external host successfully connected to an internal host on RDP.
Why it's wrong here
The log entry starts with 'Deny', indicating the connection was blocked, not allowed. Therefore, it was not successful. The presence of 'Deny' is critical; if it were 'Built' or 'Allow', then it would indicate success. The analyst must recognize that denied connections do not establish sessions.
- ✗
An internal host attempted to connect to an external host on RDP, but the connection was blocked.
Why it's wrong here
The source is 'outside' and destination is 'inside', so the connection is inbound, not outbound. The internal host is the destination, not the source. Also, the source port is 443, which is typically used for HTTPS, but the destination port is 3389 (RDP). The direction is misread in this option.
- ✓
An external host attempted to connect to an internal host on RDP, but the connection was blocked by the firewall.
Why this is correct
The log shows a denied TCP connection from an external IP (203.0.113.5) on port 443 to an internal IP (10.1.1.10) on port 3389. Port 3389 is used for RDP. The firewall denied the connection, indicating an attempt to access RDP from the outside was blocked. This is a common indicator of scanning or exploitation attempts.
- ✗
An internal host attempted to connect to an external host on HTTPS, but the connection was blocked.
Why it's wrong here
The source is 'outside' and destination is 'inside', so the connection is from external to internal, not the other way around. Additionally, the destination port is 3389 (RDP), not 443 (HTTPS). The source port is 443, which is unusual for an external host but does not change the direction. The log clearly shows an inbound connection attempt.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.